candid
Candid Library for the Internet Computer
Activity
- Latest release
- 1mo ago
- Total releases
- 119
- Cadence
- ~16 days
- Last 12 months
- 16
Reach
- Downloads
- 4.8M
- Stars
- 301
Details
- License
- Apache-2.0
- First release
- May 14, 2020
| Version | Released | |
|---|---|---|
0.10.35
patch
|
0.10.35
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.34
unknown
|
0.10.34
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.33
unknown
|
0.10.33
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.32
unknown
|
0.10.32
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.31
unknown
|
0.10.31
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.30
unknown
|
0.10.30
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.29
unknown
|
0.10.29
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.28
unknown
|
0.10.28
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.27
unknown
yanked
|
0.10.27
unknown
yanked
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.26
unknown
|
0.10.26
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.25
unknown
|
0.10.25
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.24
unknown
|
0.10.24
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.23
unknown
|
0.10.23
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.22
unknown
|
0.10.22
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.21
unknown
|
0.10.21
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.20
unknown
|
0.10.20
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.19
unknown
|
0.10.19
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.18
unknown
|
0.10.18
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.17
unknown
|
0.10.17
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.16
unknown
|
0.10.16
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.15
unknown
yanked
|
0.10.15
unknown
yanked
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.14
unknown
|
0.10.14
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.13
unknown
|
0.10.13
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.12
unknown
|
0.10.12
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.11
unknown
|
0.10.11
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.10
unknown
|
0.10.10
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.9
unknown
|
0.10.9
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.8
unknown
|
0.10.8
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.7
unknown
|
0.10.7
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.6
unknown
|
0.10.6
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.5
unknown
|
0.10.5
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.4
unknown
|
0.10.4
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
0.10.3
unknown
|
0.10.3
unknown
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
0.10.2
unknown
|
0.10.2
unknown
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
0.10.1
unknown
|
0.10.1
unknown
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
0.10.0
unknown
|
0.10.0
unknown
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
0.9.11
unknown
|
0.9.11
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.9.10
unknown
|
0.9.10
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.9.9
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.9
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.9.8
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.8
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.9.7
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.7
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.9.6
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.6
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.9.5
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.5
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.4
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.4
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.3
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.3
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.2
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.2
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.1
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.1
unknown
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
0.9.0
unknown
1 CVE
CVE-2023-6245
GHSA-7787-p7x6-fq3j
RUSTSEC-2023-0073
Dec 08, 2023
Candid infinite decoding loop through specially crafted payload
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe Candid library causes a Denial of Service while parsing a specially crafted payload with Canisters using affected versions of candid are exposed to denial of service by causing the decoding to run indefinitely until the canister traps due to reaching maximum instruction limit per execution round. Repeated exposure to the payload will result in degraded performance of the canister. For asset canister users, Unaffected
PatchesThe issue has been patched in WorkaroundsThere is no workaround for canisters using the affected versions of candid other than upgrading to patched version. ReferencesFixed in
0.9.10
References
Updated May 04, 2026 · Source: OSV.dev |
0.9.0
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.9.0-beta.4
unknown
|
0.9.0-beta.4
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.9.0-beta.3
unknown
|
0.9.0-beta.3
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|